cbcvebase.
CVE-2020-5274
published 2020-03-30

CVE-2020-5274: In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In…

PriorityP428medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
1.20%
64.6th percentile
In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only display in debug configuration. This issue is patched in symfony/http-foundation versions 4.4.5 and 5.0.5

Affected

13 ranges
VendorProductVersion rangeFixed in
debiansymfony< symfony 4.4.8-1 (bookworm)symfony 4.4.8-1 (bookworm)
sensiolabssymfony>= 4.4.0 < 4.4.44.4.4
sensiolabssymfony>= 5.0.0 < 5.0.45.0.4
symfonyerror-handler>= 4.4.0 < 4.4.44.4.4
symfonyerror-handler>= 5.0.0 < 5.0.45.0.4
symfonysymfony
symfonysymfony
symfonysymfony>= 0 < 4.4.8-14.4.8-1
symfonysymfony>= 0 < 4.4.8-14.4.8-1
symfonysymfony>= 0 < 4.4.8-14.4.8-1
symfonysymfony>= 0 < 4.4.8-14.4.8-1
symfonysymfony>= 4.4.0 < 4.4.44.4.4
symfonysymfony>= 5.0.0 < 5.0.45.0.4

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv5.4MEDIUM
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.